
There is a price Bitcoin pays every day that never appears on a chart with a label. It is not priced in fear or hype but in doubt. The quiet, rational doubt that the most decentralized money ever built can actually agree to defend itself in time.
Some of the sharpest allocators in the market believe that doubt is already worth as much as a third of the price.
If they are right, Bitcoin is trading at a discount, and the strange part is that it has very little to do with quantum computers themselves.
The clearest voice on this is Capriole Investments’ Charles Edwards, who has put a number on it. He marks Bitcoin’s fair value well above its price, and explains the gap with a single fact: the network has no adopted plan to defend its cryptography against a quantum computer.
The expiration date nobody printed on the label
Most people hold Bitcoin as if it were a law of nature, something discovered rather than written. It’s a flattering way to own an asset, and it is mistaken.
Bitcoin is software, and the cryptography that proves who owns what is software with a shelf life. A sufficiently capable quantum computer, the kind serious researchers now expect before the next decade, could take a public key the network has already seen and work backward to the private key behind it. The lock that proves a coin is yours can, in time, be picked.
This is no longer a fringe anxiety traded among cryptographers, and it’s concrete enough that a credible investor can argue the market is already applying a haircut and be taken seriously when he does.
The danger is in the signature, not the mine
It helps to be precise about what is actually at risk, because most coverage is not.
Quantum computing does not threaten Bitcoin’s supply, its halving schedule, or the slow predictable drip of new issuance.
It threatens ownership, and only ownership.
The vulnerable part is the digital signature, the cryptographic proof you produce when you move your coins. Mining is a far smaller concern, since the quantum speedups that apply there chip at the edges of SHA-256 without coming close to breaking it.
So the dangerous surface is narrow, well mapped, and, already fixable. The wider world has been preparing for years: NIST finalized its post-quantum signature standards in August 2024, and the national security agencies have published migration timelines that already push vendors to build the tooling.
The cryptography, in other words, is the solved part of this problem.
The threat stopped being theoretical
What has changed lately is the speed.
The estimated cost of breaking Bitcoin’s signatures has collapsed in public, paper by paper: from roughly nine million qubits a few years ago to under five hundred thousand in Google’s most recent work, and in some neutral-atom designs to the low tens of thousands.
None of this breaks Bitcoin today. All of it pulls the date closer, and it is moving faster than the network’s capacity to answer.
The hard part was never the cryptography
And yet the discount persists, because the word “consensus” hides two very different things, and Bitcoin’s strength in one is its weakness in the other.
There is on-chain consensus, the mechanical agreement among nodes about which blocks are valid, and Bitcoin is superb at it. Then there is social consensus, the human process of deciding which rules should change and when, and here there is no node to run and no algorithm to settle the matter.
It happens through proposals, mailing lists, conference arguments, and the occasional message a miner buries in a block header.
No one holds the authority to break a tie, to end deadlock, and that is true by design. That design is the whole point of Bitcoin. It is also what makes a deadline-bound cryptographic migration so hard to picture.
How hard is not a matter of opinion.
Ethan Heilman, a co-author of the BIP-360 proposal, the proposal usually cited as Bitcoin’s first step toward a quantum migration, estimates that even in the optimistic case, where everyone agrees on the path tomorrow, full protection would take about seven years.
Roughly two and a half years to review and test the change, half a year to activate it, and several more for wallets, exchanges, and Lightning to follow.
Seven years is the best case.
But BIP-360 is not a post-quantum solution.
It introduces a new address type, P2MR (pay to Merkle root), that is compatible with post-quantum signatures but does not contain them. The opcodes those signatures need do not exist in Bitcoin yet, and adding them takes another fork, another round of the same consensus fight. Even the holders who move to P2MR early will have to migrate a second time, to real post-quantum addresses, once those exist.
There is a final twist.
A P2MR address hides the script that will spend it until the moment it is spent, so the network cannot cleanly watch the migration happen. The one coordination problem Bitcoin most needs to see clearly is the one its own privacy keeps partly out of view.
An immune system tuned to reject change
Think of Bitcoin’s governance as an immune system built to attack anything unfamiliar. For most of the network’s life that has been a gift, because a careless change to money can be catastrophic and there is realistically only one chance to migrate cleanly.
But an immune system that treats every intervention as a threat cannot tell a poison from a medicine.
When the change the body needs is urgent and comes from outside, the very machinery that kept it safe begins to work against it. Bitcoin will, I am sure, coordinate a contentious cryptographic migration with all the speed and unity it once brought to the block size war.
The point is not that Bitcoin cannot move. It is that its timeline for moving is set by culture, while the threat is running on a calendar of its own, and the gap between those two clocks is what the market has begun to price.
Credibility, not code, is the catalyst
The discount does not close when a migration ships.
It closes earlier, the day the market decides a workable one credibly will.
What moves the price is the belief, not the code, and that belief does not sit still while everyone waits.
Charles Edwards argues it compounds: every year without a credible plan, the market must price a larger chance that Bitcoin runs out of runway, so the longer the silence holds, the deeper the haircut grows.
An asset the market cannot confidently price tends to trade cheap for a long stretch, then reprice all at once the moment credible, decision-relevant information arrives.
A plan that earns that belief has to be legible to engineers and investable to institutions at the same time:
- A short list of signature candidates with honest trade-offs.
- The safe option made the default for ordinary holders.
- An explicit answer for coins that will never migrate.
- An activation path that minimizes the risk of a chain split.
- Visible commitment from the wallets, exchanges, and custodians who would have to carry it out.
Every credible step toward that should compress the discount.
Until such a plan exists in the open, it stays and grows.
The move Bitcoin cannot make
All of this points to an uncomfortable asymmetry. The mathematics has been ready for over a year. The agreement to deploy it has not formed, and no one can name the date it will.
That is not a quantum problem in any meaningful sense but the standing cost of a system engineered to resist exactly the kind of decisive, time-bound action this moment asks for.
There is, of course, another way to reach quantum security, and it goes unmentioned because it is undramatic: build the chain quantum-secure from its first block, so there is no migration to coordinate, no governance fight to win, and no discount to charge. Of course, the tradeoff is that for such chain, the migration problem becomes an adoption problem.
A network that never inherited the problem is not waiting on a consensus that may never form in time.
That is simply the option that Bitcoin, by its own nature, does not have.
The distance between two clocks
So watch the two clocks.
One is public and quantifiable: the qubit estimates falling paper by paper, an attack that reads like science fiction a few years ago looks a little more like engineering each quarter.
The other is invisible and cultural: the slow formation of agreement among people who have made a virtue of refusing to be hurried.
Bitcoin’s quantum discount lives in the distance between them.
The real question for anyone holding the asset is not whether the cryptography can be fixed, because it can, and it largely has been. The question is whether the most successful experiment in decentralized coordination can coordinate, on a deadline it did not choose, the one upgrade it cannot afford to get wrong.
Related Posts




